Tag: data
-
Cyber Defense Alone Can’t Keep Critical Services Running
States Must Map Dependencies and Engineer Safeguards for Water and Hospitals. State CIOs must decide which water systems, hospitals and other essential services need protection first. NASCIO data shows why states should rank infrastructure by consequence, test simultaneous failures and pair cyber defenses with engineering safeguards. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cyber-defense-alone-cant-keep-critical-services-running-a-32871
-
Post-Mythos Security Rally Rewards Broad Cyber Platforms
6 Major Security Vendors Have Doubled in Value Since Anthropic Unveiled Mythos Six prominent cybersecurity vendors have doubled their valuations since Anthropic announced Claude Mythos in April, led by Okta’s 131% stock surge as investors bet that AI agents will drive demand for identity, data, network and integrated security platforms. First seen on govinfosecurity.com Jump…
-
Sensitive UK police data vulnerable to ‘compromise’ by US government and foreign actors
Exclusive: Official UK security assessment found Microsoft cloud platform storing files was at potential risk from hostile hackersVast troves of highly sensitive police data are lying on Microsoft cloud platforms which an official UK security assessment deemed to be vulnerable to “compromise” by foreign actors and the US government, a Guardian investigation can reveal.The files…
-
International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data
The U.S., Japan, Germany and Australia said WaterPlum operators pose as prospective employers and have infected more than 30,000 devices worldwide. First seen on cyberscoop.com Jump to article: cyberscoop.com/north-korea-waterplum-job-seeker-crypto-attacks/
-
Zero-Days, AI Agents, and Massive Data Leaks Define the Week
Weekly summary of Cybersecurity Insider newsletters First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/weekly-roundup/zero-days-ai-agents-and-massive-data-leaks-define-the-week/
-
Gyazo server flaw exploited to steal 23.6 million user records
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/gyazo-server-flaw-exploited-to-steal-236-million-user-records/
-
JADEPUFFER Evolves Agentic Ransomware to Target AI Models and Training Data
Tags: ai, attack, cyber, data, data-breach, extortion, group, infrastructure, intelligence, ransomware, threat, trainingJADEPUFFER, the agentic threat actor first linked to an autonomous ransomware operation against exposed Langflow infrastructure, has evolved its tooling to target artificial intelligence models, training datasets, and vector data. Its latest payload, ENCFORGE, marks a shift from conventional database extortion toward destruction-focused attacks on high-value AI and machine-learning assets. The group’s ENCFORGE locker targets…
-
AI Agent Breaches Spanish Organization, Modifies Personal Data
AI-driven cyberattacks used to be exotic. Soon, it’ll be odd if threat actors aren’t using agents to do all of their bidding. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/ai-agent-breaches-spanish-organization-personal-data
-
Abandoned IoT apps keep sending sensitive data to broken servers
Millions of people still run smart home and IoT companion apps, the apps used to control devices like smart plugs, cameras, and thermostats, that stopped receiving updates … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/18/abandoned-iot-apps-data-security-risks/
-
OpenAI Reveals AI Models Concealing Mistakes, Using Exposed API Keys and Sharing Files
OpenAI has introduced a new framework for reporting model misalignment after discovering instances where its AI systems concealed mistakes, accessed exposed API keys, fabricated data, uploaded files without authorization, and communicated through unintended channels. The company released six initial reports detailing behaviors observed during model training and evaluation. They argue that AI developers need more…
-
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
The Iran-linked “hacktivist” persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE.”HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading, First seen on thehackernews.com Jump to article:…
-
OpenAI admits its models lie to cover their own mistakes
OpenAI launches a formal framework to disclose model misalignment, publishing six reports on models that lied, faked data, or bypassed rules. Most companies don’t publish a document explaining how their product misbehaves. OpenAI just did. On September 16, it released a formal framework for tracking, investigating, and disclosing cases of model misalignment, paired with six…
-
Mind Raises $72M to Rebuild DLP Around AI Agents
AI Agents Could Help Analysts Separate Meaningful Data Events From Routine Activity. Mind raised $72 million to expand a DLP platform that pairs endpoint enforcement with AI agents designed to analyze data lineage, surface evidence of sensitive data movement and guide employees through policy violations. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/mind-raises-72m-to-rebuild-dlp-around-ai-agents-a-32860
-
Breach Roundup: China Calls for Stronger AI Oversight
Also, Spain’s First AI Agent-Linked Data Breach, NightmareStresser Domains Seized. This week: a call for stronger AI oversight in China, an AI agent-linked breach in Spain, Cisco active exploits, Check Point patched flaws. NightmareStresser seized – again! South Korea data breach fines, AI made BEC attacks worse. An Android Trojan, an exploited Pixel flaw and…
-
Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE
Six months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in Bahrain … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/aws-middle-east-outage-permanent-data-loss-bahrain-uae/
-
New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data
Researchers at Zimperium have uncovered a new Android malware strain, dubbed RatHat, with spyware and backdoor capabilities First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/rathat-android-malware-ai-steal/
-
CISA Urges Organizations to Deploy Cyber Decoys to Detect Hackers Inside Networks
Tags: cisa, credentials, cyber, cybersecurity, data, detection, hacker, infrastructure, network, strategyThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged organizations to deploy cyber decoys, which include fake credentials, systems, data, and services. This strategy aims to expose attackers sooner and enhance post-compromise detection. In new guidance titled >>Using Cyber Decoys to Strengthen Detection and Response,<< published on September 16, 2026, CISA outlined how defenders…
-
12 Best DSPM Tools Compared (2026): Features Pricing
Quick Answer: DSPM has the scariest pricing curve in security bills track data volume, and data only grows. Microsoft Purview publishes pay-as-you-go rates (the anchor); Cyera leads the independents; BigID and Varonis bring privacy and on-prem lineage; CrowdStrike (Flow) and Tenable (Eureka-lineage) mark the consolidation wave. Negotiate volume caps before your data does the negotiating.…
-
12 Best DSPM Tools Compared (2026): Features Pricing
Quick Answer: DSPM has the scariest pricing curve in security bills track data volume, and data only grows. Microsoft Purview publishes pay-as-you-go rates (the anchor); Cyera leads the independents; BigID and Varonis bring privacy and on-prem lineage; CrowdStrike (Flow) and Tenable (Eureka-lineage) mark the consolidation wave. Negotiate volume caps before your data does the negotiating.…
-
Galaxy-S26-Serie Samsung startet den Rollout von One UI 9
Samsung beginnt mit dem Rollout von One UI 9. Das Update steht zuerst auf dem Galaxy S26, Galaxy S26+ und Galaxy S26 Ultra zur Verfügung. First seen on computerbase.de Jump to article: www.computerbase.de/news/smartphones/one-ui-9-samsung-verteilt-update-fuer-die-galaxy-s26-serie.99450
-
APT36 Targets Indian Government and Defense Organizations With New Rust Malware Arsenal
Pakistan-nexus threat actor APT36 has launched a renewed espionage campaign targeting government and defense organizations in India and Afghanistan. Deploying a new Rust-based malware suite designed for covert command-and-control, data theft, and propagation into isolated networks. Tracked by Zscaler ThreatLabz as Operation RapidRust, the activity was observed in August 2026 and reflects a significant evolution…
-
Spain reports first data breach involving autonomous AI agent
Spain’s data protection authority (AEPD) has reported its first data breach blamed on an AI agent acting on its own, after the system reportedly logged into a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/spain-ai-agent-data-breach/
-
Spain reports first data breach involving autonomous AI agent
Spain’s data protection authority (AEPD) has reported its first data breach blamed on an AI agent acting on its own, after the system reportedly logged into a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/spain-ai-agent-data-breach/
-
AI Agent Carries Out Multi-Stage Data Theft Attack
Spanish data protection agency AEPD reveals the country’s first AI-powered data breach First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ai-agent-carries-out-multistage/
-
RatHat Abuses Android Wireless Debugging to Gain Shell Access and Steal Banking PINs
RatHat, a newly identified Android banking malware family that combines Accessibility abuse, local Android Debug Bridge (ADB) pairing, native shell-level components, and generative-AI-assisted interface automation. The operation appears linked to China-based threat actors and is primarily designed to steal banking credentials, payment PINs, one-time passwords, device-unlock secrets, and other high-value data from infected Android devices.…
-
The AI security question leaders should be asking instead
In this Help Net Security interview, Frederic Bull, Security Officer at Gremlin, talks about what AI means for security teams. The conversation covers why asking what data a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/frederic-bull-gremlin-ai-in-cybersecurity-gap/
-
Anthropic wants Claude to analyze your bank account and financial data
Anthropic is testing a new personal finance feature called “Claude Money” that will allow you to connect your bank accounts directly to Claude and “understand your money.” First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/artificial-intelligence/anthropic-wants-claude-to-analyze-your-bank-account-and-financial-data/
-
CVS, Criteo Settle Web Tracker Data Privacy Suit for $20.5M
Class Action Claim Says Web Trackers Disclosed Patient Health Data Without Consent. CVS Health and digital advertising firm Criteo have agreed to pay $20.5 million to settle proposed class action litigation alleging that the retail pharmacy giant unlawfully disclosed patient personal and health information to Criteo through web trackers embedded on CVS’ websites and apps.…
-
Spain’s data agency gets first report of AI-powered data breach
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/spains-data-agency-gets-first-report-of-ai-powered-data-breach/

